Method and apparatus for an encryption system
Summary by NHIP
Encryption system with server and user ends
The system records writable actions on user ends and encrypts files to prevent unauthorized information outflow. It utilizes a server database, an active directory module employing Lightweight Directory Access Protocol, and user-end code function modules that distinguish ordinary files from secure files via a secure set.
Claim Score by NHIP
Abstract
This invention relates to a method and apparatus for an encryption system. The encryption system includes a server end and user's ends, in which the whole writable action about information outflow is recorded by the server end. The method of the present invention is used for encrypting the writable file by the user's ends to avoid unauthorized information outflow through out-connecting storing equipment. Therefore, all the files are just used within the Intranet of the company and the security system. Thus, the purpose of protecting information is achieved.

Term
Projected expiry 11 August 2029.
- Priority and filed
- Granted
- Today
- Projected expiry
16 claims: 2 independent, 14 dependent
- 1An encryption system, comprising a server end and least one of user's ends; the encryption system is operative to record the whole writable action by the user's ends, and encrypt writable files by the user's ends to avoid information overflow from an entrusted network; the encryption system comprising:the server end for receiving and delivering information, organizing and managing information, storing a secure set and using records of the user's ends, and updating function to surely set data at the user's ends;and database of the server end, for providing one space to store data of the server end and other input data, and directly accessing the stored data;a managing interface module, for providing an managing interface to a system operator directly to request and manage the server;an active directory module, for receiving information of company members and department groups, and for restoring database of the server end through Lightweight Directory Access Protocol (LDAP);an interface of delivering and receiving information of the user's ends, for receiving information from the user's ends, restoring information into database of the server end, and delivering information from the server end;the user's ends, which are used for receiving transmitted information, writing an ordinary file and a secure file to encrypt the information by using a single machine through the secure set, the user's ends at least comprising: a database of the user's ends, for providing one space to store data of the user's ends and input data to directly access the data;a code function module, which is a protection mechanism to avoid unauthorized outflow of information from the user's ends, for examining difference between the ordinary file and the secure file through the secure set;an interface module of the user's ends, which is an interface used for reading a writable file after acquiring the secure set, encrypting the writable file to produce a secure file by using an encryption key;after sending the secure file to an output storage equipment, the interface module of the user's ends requests the code function module to pass the secure file;a delivering data module, for delivering the secure file to the output storage equipment when the secure file passes said code function module, and delivering the encryption key to database of the server;an external accessing data module, for recording the secure file on recording medium after receiving the secure file by the output storage equipment;and a delivering and receiving data interface of the user's ends, for receiving information of the server end, restoring into database of the user's ends, and delivering information from the user's ends.
- 6Broadest claimClaim Score 46, average(NHIP)An encryption method, which is used for completely recording a plurality of whole writable steps and encrypting writable files by using an encryption key to avoid information overflow from an untreated network, the encryption method comprising steps of:setting a database of a server end, and maintaining function through a server end;the user's ends connected to the server end through the Internet by selecting various modes;the user's ends acquiring and confirming the newest data of the server end, and operative with a single machine, examining whether a command which is about writing files out into an out-connecting storage equipment exists or not;the user's ends acquiring a secure set from database of the user's ends;the user's ends examining whether the writable files are controlled according to the secure set;the user's ends encrypting and delivering the files to the out-connecting storage equipment, and the files are set as a secure file with using an encryption key;the output storage equipment storing the encrypted files on a recording medium;and storing recorded writable files and the encryption key into database of the server end.
Independent claims2
37 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
1. Field of the Invention
The present invention relates to and method and apparatus for an encryption system, more particularly to protecting and preventing the Intranet information from unauthorized outflow.
2. Description of the Related Art
Devices for processing data and relative techniques for communication are becoming increasingly popular and widely used. Therefore, devices with various functions to process data have been developed. With the advance of computer technology, surrounding equipment for processing data are enhanced to match the modern needs and manufacturing competition has accordingly increased. However, other relative security problems arise at the same time, such a dispersion system of the Intranet.
The dispersion system comprises a plurality of user's ends s and the server end. The information flow is quite amazing. However, for avoiding unauthorized outflow of internal information, several methods are provided, such a firewall□anti-virus program of the security system, which is used to avoid hacker attacks or information outflow through the Internet. No special protection methods are currently disclosed to avoid data outflow as using out-connecting storing equipment, especially concerning CD-Rs.
As the size of CD-Rs gradually decreases, the problems of easily removing unauthorized copied files are generated. According to the purpose of the invention, various methods for protecting files are proceeded with various strategies. The critical point is that the user's ends needs to link up with the server end for passing information after acquiring authorization when the Intranet information begins outflow, or encrypting the information through the server end, and then delivering the dummy information back to the user's ends. Through this way, huge loading is produced within the local Intranet, and the velocity of communication is decreased. Because the Intranet multi-connections of the Internet are preceded within the huge Intranet, at the same time, the resource of the system is occupied. Therefore, with back-and-forth delivering information, significant time is wasted. With application of modern techniques, similar situations will not happen.
As described above, how to make data flow of the Intranet be secure yet able to be encrypted by the ordinary users has remained quite practical according to the present invention.
SUMMARY OF THE INVENTION
In view of the aforesaid aspect, a method and an apparatus for an encryption system is provided according to the present invention.
According to main object of the present invention, writable files are encrypted through the user's ends so as to avoid data outflow through out-connecting storing equipment, so information security is not damaged and the benefits of a company are not risked
According to the present invention, the encryption system and method at least comprises: setting up a database and maintaining function through the server end; with various selection modes, connecting with the server end through the Internet; acquiring and confirming the newest data from the server end; processing with a single machine at the user's ends; examining whether the command of controlling and sending the writable file to out-connecting storing equipment exists by the user's ends; and acquiring security set from database of the user's ends. The user's ends examines whether the writable files are controlled and encrypted by using an encryption key after acquiring data; encrypting the information according to the security set; delivering the files to out-connecting storing equipment and then setting them as secure files; storing the encrypted files into recording media by out-connecting storing equipment; and, restoring the recorded files into the database of the server end by using the encryption key.
The objects, features, and effects of the present invention will be more readily understood from the following detailed description of the preferred embodiments with the appended drawings.
BRIEF DESCRIPTION OF THE DRAWINGS
<figref idrefs="DRAWINGS">FIG. 1</figref> is a structure diagram of an encryption system according to the present invention;
<figref idrefs="DRAWINGS">FIG. 2</figref> is a schematic diagram of writing data onto out-connecting storing equipment of the user's ends according to the present invention;
<figref idrefs="DRAWINGS">FIG. 3</figref> is a diagram showing the relation between a server end and a plurality of user's ends s according to the present invention;
<figref idrefs="DRAWINGS">FIG. 4</figref><i>a </i>is a flowchart <b>1</b> of the encryption method according to the present invention;
<figref idrefs="DRAWINGS">FIG. 4</figref><i>b </i>is a flowchart <b>2</b> of the encryption method according to the present invention;
<figref idrefs="DRAWINGS">FIG. 5</figref> is a detailed flowchart of setting up a database of user's ends according to the present invention;
<figref idrefs="DRAWINGS">FIG. 6</figref><i>a </i>is a detailed flowchart <b>1</b> of an active Internet mode of the user's ends according to the present invention;
<figref idrefs="DRAWINGS">FIG. 6</figref><i>b </i>is a detailed flowchart <b>2</b> of an active Internet mode of the user's ends according to the present invention;
<figref idrefs="DRAWINGS">FIG. 7</figref><i>a </i>is a detailed flowchart showing a passive Internet mode of the user's end, which is informed to change set through the server end;
<figref idrefs="DRAWINGS">FIG. 7</figref><i>b </i>is a detailed flowchart showing a passive Internet mode of the user's ends, which delivers changing set through a server end.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
A method and apparatus for an encryption system and method to avoid unauthorized information outflow for protecting data of a company are disclosed. Referring to <figref idrefs="DRAWINGS">FIG. 1</figref>, it is a structure diagram of an encryption system according to the present invention.
The structure of the system of the present invention includes: the server end <b>100</b> and at least one user's end <b>200</b>; the user's end <b>200</b> connecting to the server end <b>100</b> through the Intranet; recording the whole writable action by the server end; encrypting the writable files through the user's ends to avoid data outflow; receiving and delivering data by the server end <b>100</b>; integrating and managing information of the company; storing the secure set and using records of the user's end <b>200</b>; updating function of the secure set information at the user's end <b>200</b>; the function includes: (1) managing interface module <b>110</b> (2) database of the user's ends <b>120</b> (3) active directory module <b>130</b> (4) delivering and receiving interface of the server end <b>140</b>; further explaining as follows: (1) managing interface module <b>100</b>, which provides a managing interface to directly request and control the server end <b>100</b>; (2) database of the server end <b>120</b>, which provides one space to restore data of the server end and other input data so as to directly access the data; (3) active directory module <b>130</b>, which is used to acquire information of a company and department groups through Lightweight Directory Access Protocol (LDAP) and restore the information into a database of the server end <b>120</b>. (4) delivering and receiving interface of the server end <b>140</b>, which is used for receiving information from the user's end <b>200</b>, restoring information into database of the server end <b>120</b>, and delivering information from the server end <b>100</b>.
The user's end <b>200</b>, which is used for receiving and delivering information, is operated with a single machine. The secure set is used by the user's end <b>200</b> to write an ordinary file and a secure file for encrypting information. The user's end <b>200</b> comprises: the code function module <b>210</b>□database of the user's end <b>220</b>□interface module of the user's end <b>230</b>□delivering and receiving interface of the user's end <b>240</b>□delivering data module and extra-storing data module. The user's end <b>200</b> is further described as follows: (1) the code function module <b>210</b>, which is a protection mechanism to prevent data outflow of the user's end <b>200</b>; examining the difference between the ordinary file and the secure file through the secure set; the ordinary file is not encrypted with the encryption key and presented by an enclosed document; (2) database of the user's end <b>220</b>, which provides one space for restoring information of the user's end <b>200</b> and input data, and directly accesses the secure file; the secure file is encrypted by using the encryption key and presented by an enclosed document; (3) interface module of the user's end <b>230</b>, which is a user interface, and used for reading a writable file after acquiring the secure set; then, encrypting the writable file to produce a secure file by using an encryption key; sending the secure file to an out-connecting storing equipment <b>262</b>, and requesting the code function <b>210</b> to pass the secure file; (4) delivering and receiving interface of the use's end <b>240</b>, which is used for receiving data from the server end <b>100</b>, restoring into database of the use's end <b>220</b> and delivering the data from the user's end <b>200</b>; (5) the delivering data module <b>250</b>, which is used to deliver the secure file to an out-connecting storing equipment <b>262</b> after the encryption key is delivered to database of the server end <b>120</b>; (6) extra-storing data module <b>260</b>, which is used to receive and store the secure file into recording medium after receiving the secure file by the out-connecting storing equipment. The foregoing secure set includes various users' names and specific machine signals on a computer.
The encryption method of the use's end <b>200</b> is proceeded by using an asymmetric encryption key and a symmetric encryption key. Therein, the asymmetric encryption key is selected from any of PKI□RSA Algorithm or elliptic curve code, and the symmetric encryption key is selected from any of Blowfish□AES□Triple DES□DES□IDEA□RC5□CAST-128 and RC2. The foregoing out-connecting storing equipment is selected from floppy disk driver□CD-R□ ZIP□MO□ recording device□Universal Serial Bus(USB)□connection line connecting to a Universal Serial Bus□connection line of Parallel Port□connection line of Serial Port and movable storing data device.
Otherwise, the out-connecting storing equipment <b>262</b> is collocated by using a recording medium. The recording medium is selected from recordable CD-R□recordable magnetic disk recordable driver and memory. The foregoing server end <b>100</b> stores a recorded writable file. The recorded file at least includes the following columns: time for writing files, an identifier code of computer machine, a users' name, the name of writable file, thumbprint of files (SHA1 information structure) and random pieces of content. Referring to <figref idrefs="DRAWINGS">FIG. 2</figref>, it is a diagram for writing data into out-connecting storing equipment by the user's ends. When delivering files to the out-connecting storing equipment <b>262</b> by the user's ends, the file is encrypted to produce the secure file <b>264</b> through the encryption method aforesaid, and then through the foregoing encryption method the secure file <b>264</b> is encrypted with using an encryption key. If the encrypted secure file is opened, the encrypted secure file will be presented with an unreadable folded document.
<figref idrefs="DRAWINGS">FIG. 3</figref> is a diagram showing the relation between the server end and a plurality of user's ends s according to the present invention and it mainly explains the server end <b>100</b> through receiving interface of the server end <b>140</b>. <figref idrefs="DRAWINGS">FIG. 3</figref> is mainly used to describe a server end <b>100</b> which respectively connects to the <b>200</b><i>a</i>˜<b>200</b><i>n </i>receiving interface of the <b>240</b><i>a</i>˜<b>240</b><i>n </i>delivering user's ends through delivering and receiving interface of the server end <b>140</b>. Thus, fast delivering is achieved.
Referring to <figref idrefs="DRAWINGS">FIG. 4</figref><i>a </i>and <figref idrefs="DRAWINGS">FIG. 4</figref><i>b</i>, it is a flowchart <b>1</b> of the encryption method to avoid data outflow according to the present invention. <figref idrefs="DRAWINGS">FIG. 4</figref><i>b </i>is a flowchart <b>2</b> of the encryption method to avoid data outflow according to the present invention. It is described as follows: first, setting a database <b>120</b> of the server end through the server end <b>100</b>, and maintaining function of the database <b>120</b> (step <b>400</b>), referring back to the step A.
Referring to <figref idrefs="DRAWINGS">FIG. 5</figref>, it is a detailed flowchart about setting up a database of the server end according to the present invention.
After step A, setting up a managing interface module <b>110</b> which is used to enter database of the server <b>120</b> and access the data (step <b>402</b>). Next, acquiring data of company members and department groups through an active directory module <b>130</b> (step <b>404</b>). Finally, storing data into database of the server end <b>120</b> (step <b>406</b>). Then referring back to <figref idrefs="DRAWINGS">FIG. 4</figref><i>a</i>, the flow is continued after step <b>400</b>. The user's end <b>200</b> proceeds an Internet connecting (step <b>410</b>) according to various modes (step <b>410</b>). The Internet modes are divided into the active Internet mode (step <b>415</b>) and the passive Internet mode (step <b>420</b>). Respectively entering step B and step C, the two Internet modes will be explained later after describing <figref idrefs="DRAWINGS">FIG. 4</figref><i>a </i>and <figref idrefs="DRAWINGS">FIG. 4</figref><i>b</i>. First, acquiring and affirming the newest information of the server end <b>100</b>; then progressing with single machine (step <b>430</b>); next, examining whether the command of writing data onto an out-connecting storing equipment <b>262</b> exists (step <b>440</b>). If the command about writing files to out-connecting storing equipment <b>262</b> is not received, continuously monitoring by the user's end <b>200</b> (step <b>450</b>) and then back to step <b>440</b>. If receiving the command of sending writable files to the out-connecting storing equipment <b>262</b>, the user's end <b>200</b> acquires the secure set from database of the user's end <b>220</b> (step <b>460</b>). The secure set includes various users' name and specific signals. Then, the user's end <b>200</b> examines whether the files need to be controlled according to the secure set (step <b>470</b>). If the result is “no”, directly writing the file into the out-connecting storing equipment <b>262</b> (step <b>490</b>), and then setting the file as an ordinary file; storing a recorded writable file into the database of the user's end <b>220</b> (step <b>495</b>) If the result is “yes”, encrypting and delivering the files to the out-connecting storing equipment <b>262</b> by using the encryption key (step <b>480</b>); then storing the encrypted files into a recording medium (step <b>485</b>) by out-connecting storing equipment <b>262</b> (step <b>485</b>). Finally, storing a writable file into database of the user's end <b>220</b> (step <b>495</b>) and closing the flow.
After step B, the flow is explained as follows. Referring to <figref idrefs="DRAWINGS">FIG. 6</figref><i>a </i>and <figref idrefs="DRAWINGS">FIG. 6</figref><i>b</i>, <figref idrefs="DRAWINGS">FIG. 6</figref><i>a </i>is a detailed flowchart <b>1</b> of the active Internet mode of the user's ends according to the present invention. <figref idrefs="DRAWINGS">FIG. 6</figref><i>b </i>is a detailed flowchart <b>2</b> of the active Internet mode of the user end according to the present invention. After step B, acquiring one character of the user's end <b>200</b> through a database of the user's end <b>220</b> (step <b>500</b>). The character is about selectively choosing a specific machine signal on the computer and its users' name Next, sending a command of synchronous information through the delivering and receiving interface of the user's end <b>240</b> (step <b>502</b>).
After sending the command, receiving the command of synchronous information through a delivering and receiving interface of the server end <b>140</b>, and entering database of the server end <b>120</b> (step <b>504</b>) and then the database <b>120</b> of the server end comparing the characteristics of the information to determine if it is right or not. Subsequently, comparing whether the command is right with database of the server end <b>120</b> (step <b>506</b>) If the character is wrong, sending an error signal back to the user's end <b>200</b> (step <b>520</b>); setting limitation to avoid outflow by the user end <b>200</b> (step <b>522</b>). If the character is exactly right, examining whether synchronous comparison is needed by the database of the user's end <b>220</b> (step <b>510</b>). If the result is “no”, storing the recorded writable file into database of the server end <b>120</b> (step <b>540</b>). If the result is “yes”, through the delivering and receiving interface <b>140</b>, delivering the updated data to the delivering and receiving interface of the user's end <b>240</b> (step <b>530</b>). Finally, the delivering and receiving interface of the user's end <b>240</b> receives data and stores the data into the database of the user's end <b>220</b> (step <b>532</b>), and then closing the flow.
The trigger time of the active Internet mode in <figref idrefs="DRAWINGS">FIG. 1</figref> is selected from any of required information which is from the server end <b>100</b>□first Internet connect. The first Internet connect is operative after turning on or freely setting a time period by the user's end <b>200</b>. Next, describing the detail flow after step C; the step C is divided into step C1 and step C2. In step C1, the system is informed to change set (step C1). In step C2, the system directly delivers the changing set (step C2).
Referring to <figref idrefs="DRAWINGS">FIG. 7</figref><i>a </i>and <figref idrefs="DRAWINGS">FIG. 7</figref><i>b</i>, <figref idrefs="DRAWINGS">FIG. 7</figref><i>a </i>is a detailed flowchart showing a passive Internet mode of the server end. The passive Internet mode is informed to change set through the server end. <figref idrefs="DRAWINGS">FIG. 7</figref><i>b </i>is a detailed flowchart showing a passive Internet mode of the user's ends the passive Internet mode delivers a changing set through the server end.
After step C1, the server end <b>100</b> examines whether a managing interface module changes a secure set (step <b>600</b>). If the secure set is not changed, the server end <b>100</b> continuously monitors (step <b>610</b>) and goes back to step <b>600</b>; if the secure set is changed, the server end <b>100</b> informs each user end <b>200</b> to change the secure set through the delivering and receiving interface <b>140</b> (step <b>620</b>). Then, each users' end <b>200</b> receives the informing signal through delivering and receiving interface <b>240</b>, and is requested to take a new secure set back (step <b>630</b>). Finally, the server end <b>100</b> delivers a new secure set back to the user's end <b>200</b> through the managing interface module <b>110</b>, and stores the secure set into the database of the user's end <b>220</b> (step <b>640</b>), and closing C1.
After step C2, the server end <b>100</b> examines whether the secure set is changed through the managing interface module <b>110</b> (step <b>650</b>). If the secure set is not changed, the server end continuously monitors the secure set. If the secure set is changed, the server end delivers the new secure set directly to the delivering and receiving interface of the user's end <b>240</b> through the delivering and receiving interface <b>140</b> (step <b>670</b>). Finally, the delivering and receiving interface of the user's end <b>240</b> stores the new secure set into the database of the user's end <b>220</b> (step <b>680</b>).
While embodiments of the invention have been illustrated and described, it is not intended that these embodiments illustrate and describe all possible forms of the invention. The words used are words of description rather than limitation, and it is understood that various changes may be made without departing from the spirit and scope of the invention.
Contents4
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both waysCites: the store holds 3 of 4
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2007300081A1 | Cited by | United States of America | Pre-grant |
| US8185751B2 | Cited by | United States of America | Search report |
| US2005078944A1 | Cites | United States of America | Search report |
| US7382883B2 | Cites | United States of America | Search report |
| WO9944691A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| Cédric Fournet, Gurvan Le Guernic, Tamara Rezk, "A security-preserving compiler for distributed programs: from information-flow policies to cryptographic mechanisms", Nov. 2009, CCS '09: Proceedings of the 16th ACM conference on Computer and communications security, Publisher: ACM, pp. 432-441. | Non-patent | – | Search report |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 16127905 | United States of America | A | |
| US20050161279 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| US2007028305A1 | United States of America | A1 | |
| US7814552B2This record | United States of America | B2 |
39 transactions on the USPTO file
Allowed after 2 non-final rejections.
- Non-final rejections
- 2
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 12th Yr, Small EntityM2553 | M2553 | |
| Payment of Maintenance Fee, 8th Yr, Small EntityM2552 | M2552 | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Cleared by L&R (LARS)L128 | L128 | |
| Application Is Now CompleteCOMP | COMP | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Referred to Level 2 (LARS) by OIPE CSRL198 | L198 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP | |
| Fee payment procedurePAYER NUMBER DE-ASSIGNED (ORIGINAL EVENT CODE: RMPN); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| Fee paymentFPAY | FPAY | |
| Surcharge for late paymentSULP | SULP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Fee payment procedurePAYER NUMBER DE-ASSIGNED (ORIGINAL EVENT CODE: RMPN); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 07814552
- Publication, DOCDB
- 7814552
- Publication, EPODOC
- US7814552
- Application
- 11161279
- Application, DOCDB
- 16127905
- Application, EPODOC
- US20050161279
Titles
- English
- Method and apparatus for an encryption system
Patent term adjustment
- A delay
- +938 daysthe office missed an examination deadline
- B delay
- +806 dayspendency past three years
- Overlap
- −269 daysdelays counted once
- Net adjustment
- 1,475 days
Classification
- CPC, 4
- G06F21/6218
- G06F21/6209
- G06F2221/2107
- H04L61/4523
- IPC, 8
- G06F15 16
- G06F7 04
- G06F21 00
- G06F21 24
- G09C1 00
- H04L9 00
- H04L29 06
- H04N7 00
- USPC, 5
- 726026000
- 380277000
- 386259000
- 709206000
- 726002000